The table below describes the structure of a JSON file that includes metadata about a phishing attack. You can download an archive containing the JSON file via Kaspersky Threat Intelligence Portal web interface or API method.
The described fields are optional and may be omitted in the JSON file if the relevant information is not available. Also, the JSON file may contain fields that are not described in the table.
JSON fields
Field |
Description |
---|---|
|
Phishing web address. |
|
Indicator that shows whether the phishing web address redirects to another web address ( |
|
Web address which the phishing web address redirects to. |
|
Name of the brand mentioned on the web page located at the phishing web address. |
|
Date and time when the phishing web address was first detected, specified in the UNIX time stamp system (number of seconds elapsed since 00:00:00 UTC, 1 January 1970). For a web address detected for the first time, the values of the |
|
Date and time when the phishing web address was last detected, specified in the UNIX time stamp system (number of seconds elapsed since 00:00:00 UTC, 1 January 1970). |
|
Phishing web address popularity index for the last three months. |
|
Top 10 countries from which Kaspersky users have accessed the phishing web address in the last three months. |
|
IP addresses to which the phishing web address resolves. |
|
Types of stolen data. |
|
Type of attack. |
|
Section containing WHOIS information about an object. |
|
Name of an object for which WHOIS information is provided. |
|
Section containing general information about the object specified in the |
|
Date of last information update about the domain or network in the registrar database. |
|
Date of the domain or network registration. |
|
Date until which the domain registration is paid. |
|
Network ID, the unique descriptor assigned to the network by the registrar. |
|
Maximum value of the IP address range in the network. |
|
Minimum value of the IP address range in the network. |
|
DNS server name. |
|
Object status. |
|
Country code. |
|
Description of a domain or network. |
|
Network name, the unique descriptor assigned to the network by the registrar. |
|
Data source. |
|
Section containing contact information. |
|
Name of the domain or network owner. |
|
Name of the organization that owns the domain or network. |
|
Contact role (owner, admin, tech). |
|
Address where the contact is registered. |
|
Country in which the contact is registered. |
|
City in which the contact is registered. |
|
Date when the contact information was last modified. |
|
Contact registration date. |
|
Contact email address. |
|
Contact ID, the unique descriptor assigned to the contact by the registrar. |
|
Contact phone number. |
|
Contact fax number. |
|
Data source for the contact. |
|
Contact description. |